CVE-2023-0475: Go-Getter Vulnerable to Decompression Bombs
Published Feb 16, 2023
·Updated
A flaw was found in the HashiCorp go-getter package. Affected versions of the HashiCorp go-getter package are vulnerable to a denial of service via a malicious compressed archive.
Other sources
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
Affected Software
6 affected componentsFixes available
redhat/go-getter<1.7.0
1.7.0
redhat/go-getter<2.2.0
2.2.0
go/github.com/hashicorp/go-getter/v2>=2.0.0<2.2.0
2.2.0
go/github.com/hashicorp/go-getter<1.7.0
1.7.0
HashiCorp go-getter<=1.6.2
HashiCorp go-getter=2.1.1
Event History
Feb 16, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-0475.
2
What is the severity of CVE-2023-0475?
The severity of CVE-2023-0475 is medium with a CVSS score of 6.5.
3
How can I exploit CVE-2023-0475?
CVE-2023-0475 is a denial of service vulnerability and cannot be directly exploited for remote code execution or privilege escalation.
4
What are the affected versions of the HashiCorp go-getter package?
The affected versions of the HashiCorp go-getter package are up to exclusive 1.6.2 and 2.1.1.
5
How do I fix CVE-2023-0475?
To fix CVE-2023-0475, update to version 1.7.0 or higher for the HashiCorp go-getter package.